Junglewise Threat Intelligence

CVE-2026-46903: Oracle JD Edwards EnterpriseOne Tools takeover via Business Logic Infrastructure Security

CVE-2026-46903 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle JD Edwards EnterpriseOne Tools. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure components used to manage enterprise resource planning (ERP) software. A low-privileged user could exploit this flaw over the network to gain full control of the system. This could lead to a total loss of data confidentiality, unauthorized changes to business records, and disruption of critical business operations.

Technical details

A vulnerability in the Business Logic Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2) allows for improper privilege management and authentication bypass. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to achieve a complete takeover of the JD Edwards EnterpriseOne Tools environment, impacting confidentiality, integrity, and availability. The vulnerability is tracked as CWE-269, CWE-287, and CWE-306. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats